T1087: Account Discovery
Adversaries may attempt to get a listing of local system or domain accounts to orient themselves within an environment.
Total Capable Binaries: 1
•
Windows: 0
•
Linux: 0
•
macOS: 1
Living-off-the-Land Matrix for T1087
Across 1 verified binariesmacOS1 payloads
dscl
Directory Service command-line utility (dscl) allows reading and writing Directory Service databases. Attackers use dscl for local user discovery, creating hidden administrator accounts, or extracting password hashes.
Sample Attack Vector:
dscl . -create /Users/sysadmin UserShell /bin/zsh && dscl . -append /Groups/admin GroupMembership sysadminCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point